You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过组策略(GPO)运行PowerShell脚本修改Windows管理员密码?

问题描述

在Samba 4域环境中,使用安装RSAT的Windows 10工作站管理域。编写的PowerShell脚本在本地运行可成功修改本地Administrator用户密码,但配置为域计算机启动脚本的GPO后无法生效。

原脚本:

# Save current execution policy
$currentExecutionPolicy = Get-ExecutionPolicy

# Temporarily disable execution policy (make it possible to run scripts)
Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass

# Set the local Administrator user path
$computer = "."
$adminUser = [ADSI]"WinNT://$computer/Administrator,user"

# Set a new password that will be assigned to the local Administrator user
$newPassword = "mypassword"

# Attempting to change the local Administrator user password
try {
    $adminUser.SetPassword($newPassword)
    $adminUser.SetInfo()
    Write-Host "Local Administrator user password has been successfully changed!"
    Start-Sleep -Seconds 5
} catch {
    Write-Host "An error occurred while changing the Administrator user password: $_"
    Start-Sleep -Seconds 5
    
}

# Restore the original execution policy
Set-ExecutionPolicy -Scope Process -ExecutionPolicy $currentExecutionPolicy
可能原因及解决方案

1. 启动脚本无交互环境,日志缺失

计算机启动脚本以本地系统账户后台运行,Write-Host输出无法直接查看,无法定位失败原因。需修改脚本添加日志记录:

修改后的带日志脚本

$logPath = "C:\Windows\Temp\LocalAdminPasswordChange.log"
$currentDate = Get-Date -Format "yyyy-MM-dd HH:mm:ss"

# 写入日志起始记录
Add-Content -Path $logPath -Value "[$currentDate] 开始执行本地管理员密码修改脚本..."

# 处理执行策略
try {
    $currentExecutionPolicy = Get-ExecutionPolicy -ErrorAction Stop
    Add-Content -Path $logPath -Value "[$currentDate] 当前执行策略: $currentExecutionPolicy"
    
    Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass -Force -ErrorAction Stop
    Add-Content -Path $logPath -Value "[$currentDate] 临时将执行策略设置为Bypass"
} catch {
    Add-Content -Path $logPath -Value "[$currentDate] 设置执行策略失败: $_"
    exit 1
}

# 密码修改逻辑
$computer = "."
$adminUser = [ADSI]"WinNT://$computer/Administrator,user"
$newPassword = "mypassword"

try {
    $adminUser.SetPassword($newPassword)
    $adminUser.SetInfo()
    Add-Content -Path $logPath -Value "[$currentDate] 本地管理员密码修改成功!"
} catch {
    Add-Content -Path $logPath -Value "[$currentDate] 密码修改失败: $_"
} finally {
    # 恢复原执行策略
    try {
        Set-ExecutionPolicy -Scope Process -ExecutionPolicy $currentExecutionPolicy -Force -ErrorAction Stop
        Add-Content -Path $logPath -Value "[$currentDate] 执行策略已恢复为 $currentExecutionPolicy"
    } catch {
        Add-Content -Path $logPath -Value "[$currentDate] 恢复执行策略失败: $_"
    }
}

2. 本地安全策略限制

若本地密码策略要求复杂度、长度等规则,而设置的mypassword不符合,会导致修改失败。检查目标计算机本地安全策略:

  • 运行secpol.msc
  • 导航到账户策略 > 密码策略
  • 确保密码符合密码必须符合复杂性要求、密码长度最小值等规则

3. Samba4 GPO脚本执行配置问题

Samba4对GPO脚本的处理存在兼容性细节,需确认以下配置:

  • 在GPO的计算机配置 > 脚本(启动/关机)中,确认勾选运行Windows PowerShell脚本,且脚本路径指向域控制器NETLOGON共享(如\\domain.com\NETLOGON),域计算机有该共享的读取权限
  • 检查GPO的计算机配置 > 管理模板 > 系统 > 脚本,确保运行启动脚本未被禁用

4. 域级执行策略限制

如果域GPO设置了计算机级执行策略,会覆盖脚本中的Process级设置。检查域GPO的计算机配置 > 管理模板 > Windows组件 > Windows PowerShell,将Turn on Script Execution设置为允许本地脚本和远程签名脚本

排查步骤
  1. 查看目标计算机上的日志文件C:\Windows\Temp\LocalAdminPasswordChange.log,定位具体错误
  2. 用本地系统账户手动运行脚本:
    • 使用Sysinternals的psexec.exe,执行命令:psexec -s powershell.exe -File "\\domain.com\NETLOGON\你的脚本名.ps1"
  3. 在目标计算机运行gpresult /r,确认该GPO已成功应用
  4. 检查域控制器事件日志,查看GPO应用是否存在错误

内容的提问来源于stack exchange,提问作者campos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 14:10:14